IBM WebSphere Application Server Cross Site Scripting

2014.09.12
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

INFO: Class: Input Validation Error CVE: Remote: Yes Local: No Published: Aug 27 2014 12:00AM Updated: Aug 27 2014 12:00AM Credit: G. S. McNamara, CGI Federal Emerging Technologies Security Practice (ETSP) Vulnerable: IBM WebSphere Application Server (WAS) Integrated Solutions Console 7.0.0.19 DISCUSSION: IBM WebSphere Application Server (WAS) contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the login page of the Integrated Solutions Console does not validate input to the 'username' parameter before returning it to users. This may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in the 'Welcome [username]' message at the top of the dashboard page upon logging in. The finding exists in a version that was released after this class of vulnerability was patched by IBM, and so is newer than a recommended version by IBM to upgrade to for protection from this particular class of vulnerability. Subsequent releases may protect against this issue. REFERENCES: http://osvdb.org/show/osvdb/110592 http://maverickblogging.com/disclosed-xss-vulnerability-in-ibm-websphere-application-server-integrated-solutions-console/

References:

http://osvdb.org/show/osvdb/110592
http://maverickblogging.com/disclosed-xss-vulnerability-in-ibm-websphere-application-server-integrated-solutions-console/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top